ForgeApply · Job listing
Security Compliance Program Manager (Contract)
Kaizenlabs
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
Government technology has failed the public for decades, and Americans have been conditioned to expect websites from the 90s for essential public services.
Kaizen exists to strengthen trust in American public services by building technology that residents and public servants are proud to use. We partner with local, state, and federal agencies to replace legacy systems with modern, AI-native software that is worthy of the people they serve. We started in outdoor recreation, and now we're building toward something much larger — the software layer that powers how Americans access any government service.
Our platform reaches 55 million Americans across 50+ agencies. Our goal: build technology that touches the lives of 100 million residents by the end of the year.
Founded in 2022 and based in New York City, Kaizen has raised $35 million from NEA, a16z, Accel, 776, and Carpenter Capital. We're builders, designers, and operators who believe that beautifully designed software shouldn't be a luxury in government. It's how you earn trust back.
THE ROLE
Authorization status gates what Kaizen can bid and deliver. We have active federal contracts across civilian and defense agencies, and every pursuit in our pipeline turns on it.
We are standing up a dedicated compliance function and hiring for it permanently. This engagement builds the operating machinery in the meantime: the register, the calendar, the submissions, and the evidence trail. Hands-on production work rather than advisory.
THE PROGRAMS
FedRAMP. We are pursuing certification under the current Certification Class framework in a government cloud region, built on the 20x pathway rather than a legacy Rev 5 program. We are designing for reuse rather than authorizing each product from scratch, so the change-control side of an authorization matters here as much as the initial package. You would own the operations side: control implementation status, the inherited-versus-owned split, POA&M currency, continuous monitoring, Key Security Indicators, the machine-readable package, marketplace status, and the evidence flow to our independent assessor.
DoD Impact Levels. Our work spans multiple impact levels and they do not all sit in the same place. Some run in environments we operate, others inside a customer's or a partner's. You would own knowing the reciprocity map, reading a hosting platform's actual authorization coverage against the agency in front of us, and getting the control-responsibility matrix from whoever holds the boundary.
CMMC. A separate track from the product, and keeping the two separate matters: 800-53 governs what we deliver to the government, 800-171 governs how Kaizen itself handles controlled information. You would run the self-assessment against NIST 800-171 Rev 2, build a corporate CUI system security plan distinct from any product SSP, compute and maintain the SPRS score, keep the annual senior-official affirmation on schedule, and own the POA&M entries. The scoping decision is the single biggest cost lever in the program. Familiarity with the DFARS safeguarding and incident-reporting clauses matters here.
DELIVERABLES
What we expect to have in hand at each stage.
Weeks 1 to 4
- An obligation register covering every federal contractual and regulatory requirement Kaizen carries, with its source, cadence, and owner. This means reading the contracts and subcontracts for FAR and DFARS flowdowns, not just the security frameworks. Expect employee notices, required training, prohibited technology, EEO and labor reporting, and OCI alongside the control work
- A monthly POA&M process stood up, with the first cycle assembled and submitted to our platform partner on schedule. Version one can be a spreadsheet with ten honest rows
- An obligation calendar covering every recurring deadline, each with a named owner and an escalation path
Weeks 5 to 12
- NIST 800-171 self-assessment completed and scored, with the SPRS package staged for a company official to affirm and every gap carrying a dated POA&M entry
- Control-to-evidence mapping, version one, with inherited controls separated from shared and from application-specific
- Certification application materials assembled, including a machine-readable package that validates
- A corporate CUI system security plan scoped to a named group of users, separate from the product SSP
- Federal paperwork current: DD Form 2345 and JCP registration, DD 254, PIEE and SPRS administration, SAM.gov http://SAM.gov
- Identity verification vendor evaluated and selected against FedRAMP-aligned screening requirements
Months 3 to 6
- Four plans written and usable: configuration management, incident response, contingency, supply chain risk management
- Continuous monitoring and log retention documented and running
- Agency security questionnaires answered without executive involvement
- FCL readiness package staged
WHAT YOU'LL BRING
- Direct experience submitting in federal portals, SPRS and PIEE specifically. "Supported" and "submitted" are different things
- Has run a NIST 800-171 self-assessment or RMF package end to end, with personal accountability for the outcome
- Has computed a SPRS score and can explain the mechanics without looking them up: the 110-control basis, the weighting, and what a POA&M entry does to it
- Hands-on with NIST 800-53 Rev 5 inside a real SSP, not just reading one. Knows what a control implementation statement has to say to survive an assessor
- Current on FedRAMP as it exists in 2026, and fluent in 20x specifically. Certification Classes, Key Security Indicators, machine-readable packages, continuous validation. We are building on 20x, so experience that stops at Rev 5 documentation will be working against the grain
- Knows where Rev 5 still binds. High remains a Rev 5 process and new Rev 5 certifications stop in June 2027
- Can reason about a shared authorization boundary: inherited versus shared versus applicati
Salary insight
This posting doesn't disclose pay. Across 4,674 New York jobs with disclosed salaries on ForgeApply, the median is $176k.
See full Project Manager salary data for New York →
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Kaizenlabs?
Apply in about a minuteSimilar jobs
- Security Compliance Program Manager — Kaizenlabs · New York, NY
- Staff Security Risk & Compliance Program Manager - Access Management — Confluent · Remote
- Security and Compliance Manager — Sierra · San Francisco, CA
- Security and Compliance Manager — Clinicallyai · San Diego, CA
- Security & Compliance Operations Manager — Mintlify · San Francisco
- Staff Technical Program Manager - Compliance Architecture — Zscaler · Remote
- Regulatory & Security Compliance Manager — Rain · New York, NY
- Cyber Security Program Manager — Ceribell · Sunnyvale, CA
More like this: Project & Program Manager Jobs · Project & Program Manager Jobs in New York · More jobs at Kaizenlabs · Browse all jobs